EP2828752A2

Path scanning for the detection of anomalous subgraphs and use of dns requests and host agents for anomaly/change detection and network situational awareness

Abstract

This record has no abstract on file.

EP2828752A2, drawing sheet 1
Sheet 1 of 15

Term

6.5 yearsto projected expiry

Projected expiry 14 March 2033, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

31 claims: 4 independent, 27 dependent

  1. 1
    Claims of equivalent WO 2013184206 A2 CLAIMS 1. A computer-implemented method, comprising:determining, by a computing system, historical parameters of a network to determine normal activity levels;enumerating, by the computing system, a plurality of paths in the network as part of a graph representing the network, wherein each computing system in the network comprises a node in the graph and the sequence of connections between two computing systems comprise a directed edge in the graph;applying, by the computing system, a Markov edge resolution model to the plurality of paths in the graph on a sliding window basis;and detecting, by the computing system, anomalous behavior based on the applied Markov edge resolution model.
  2. 9
    An apparatus, comprising:at least one processor;and memory storing computer program instructions, wherein the instructions, when executed by the at least one processor, are configured to cause the at least one processor to: determine historical parameters of a network to determine normal activity levels, enumerate a plurality of paths in the network as part of a graph representing the network, wherein each computing system in the network comprises a node in the graph and the sequence of connections between two computing systems comprises a directed edge in the graph, apply a statistical model to the plurality of paths in the graph on a sliding window basis, and detect anomalous behavior based on the applied statistical model.
  3. 17
    A system, comprising:memory storing computer program instructions configured to detect anomalous behavior in a network;and a plurality of processing cores configured to execute the stored computer program instructions, wherein the plurality of processing cores is configured to: determine historical parameters of a network to determine normal activity levels, enumerate a plurality of paths in the network as part of a graph representing the network, wherein each computing system in the network comprises a node in the graph and the sequence of connections between two computing systems comprise a directed edge in the graph, apply a statistical model to the plurality of paths in the graph on a sliding window basis, and detect anomalous behavior based on the applied statistical model.
  4. 24
    A computer-implemented method, comprising:collecting data, by a computing system, from a plurality of host agents pertaining to network communications sent and received by respective hosts in a network;analyzing, by the computing system, the collected data to detect anomalous behavior during a predetermined time period;and when anomalous behavior is detected, providing, by the computing system, an indication that the anomalous behavior occurred during the predetermined time period.